PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
October 20, 20250 citationsOpen Access

LLM vs. SAST: A Technical Analysis on Detecting Coding Bugs of GPT4-Advanced Data Analysis

View Full Paper
MTMadjid G. TehraniGeorge Washington UniversityESEldar SultanowUniversity of PotsdamWBWilliam J. BuchananEdinburgh Napier University

Key Points

  • GPT-4 achieved an accuracy of 94% in detecting exploitable vulnerabilities, showcasing its superiority over SAST.
  • The analysis covered 32 types of vulnerabilities, demonstrating a broad applicability of GPT-4 in security scanning.
  • Concerns were raised about the security implications of LLMs, emphasizing the need for security by design.
  • Traditional SAST tools were systematically compared to LLM capabilities, highlighting the evolving landscape of vulnerability detection.

Abstract

With the rapid advancements in Natural Language Processing (NLP), large language models (LLMs) like GPT-4 have gained significant traction in diverse applications, including security vulnerability scanning. This paper investigates the efficacy of GPT-4 in identifying software vulnerabilities compared to traditional Static Application Security Testing (SAST) tools. Drawing from an array of security mistakes, our analysis underscores the potent capabilities of GPT-4 in LLM-enhanced vulnerability scanning. We unveiled that GPT-4 (Advanced Data Analysis) outperforms SAST by an accuracy of 94% in detecting 32 types of exploitable vulnerabilities. This study also addresses the potential security concerns surrounding LLMs, emphasising the imperative of security by design/default and other security best practices for AI.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Tehrani et al. (2025) studied this question.

synapsesocial.com/papers/68f6379bb481a140a36cf6d8https://doi.org/10.48550/arxiv.2506.15212
Ask AI
Helpful
Bookmark
Share
View Full Paper